boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-754

Weakness type CWE-754 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
95804

Monthly trend

▂▁▁▁▁▁▁▁▂▁▂▁▁▁▂▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▆▃▆█▇▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 16 · 2026-06 5 · 2026-07 16 · 2026-08 22 · 2026-09 18 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-33938.798.1KEVPAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
CVE-2023-419938.897.8KEVApple Multiple Products
CVE-2023-419927.895.3KEVApple Multiple Products
CVE-2025-396829.886.4KEVtls: fix handling of zero-length records on the rx_list
CVE-2026-399298.779.4—Lakeside SysTrack Agent LsiAgent.exe Out-of-Bounds Read via UDP
CVE-2026-256397.577.8—Axios affected by Denial of Service via __proto__ Key in mergeConfig
CVE-2026-59467.576.4—Invalid handling of CLASS != IN
CVE-2024-422847.859.0—tipc: Return non-zero value from tipc_udp_addr2str() on error
CVE-2026-568126.354.9—Phoenix JavaScript presence client crashes on presence keys colliding with Object.proto…
CVE-2026-339397.553.6—Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
CVE-2026-443246.551.4—free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interf…
CVE-2026-443167.549.6—free5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 40…
CVE-2026-443227.549.6—free5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failur…
CVE-2026-733148.749.4—XenForo < 2.3.13 Signature Verification Bypass via PayPal REST Webhook
CVE-2026-691857.548.4—Socket.IO: Zero-attachment Memory Exhaustion
CVE-2026-02876.647.9—PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
CVE-2026-465417.547.3—Nimiq network-libp2p: DHT query poisoning via first-record verification failure
CVE-2026-735495.347.1—Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes on scoped…
CVE-2026-547756.546.8—CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record),…
CVE-2026-734305.346.7—Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)

Most-affected vendors